PT-2026-95980 · Noncegeek · Dim-Sum-App
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NonceGeek dim-sum-app (affected versions not specified)
Description
An issue in the Deno Backend component within the file
deno/main.tsx allows for server-side request forgery, a technique where an attacker induces the server to make requests to an unintended location. This occurs through the manipulation of the supabase url argument in the textSearchV2Handler() function. The attack can be executed remotely.Recommendations
Apply patch 8389032e5d52c28c4855c6126ca7d0eae8af346a.
As a temporary workaround, restrict the use of the
supabase url argument in the textSearchV2Handler() function.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dim-Sum-App